Executive brief
A security vulnerability exists in the Tenda CP3 IP camera, a device used for remote video monitoring. An attacker on the same network can send a specially crafted request to the camera's video streaming service, causing it to crash. This results in a denial of service where the camera stops recording or streaming video, and the official mobile app loses its connection to the device.
Technical details
A stack-based buffer overflow exists in the RTSP service of the Tenda CP3 IP camera due to insufficient length validation during URL routing and path extraction. The service utilizes a two-stage validation process for TEARDOWN requests; while the first stage checks format, the second stage fails to validate the length of the URL field during parsing. An unauthenticated attacker can trigger the overflow by establishing a valid RTSP session (completing OPTIONS, DESCRIBE, SETUP, and PLAY sequences) and then sending a TEARDOWN request containing five consecutive repetitions of a valid RTSP URL. This bypasses initial checks and overflows the stack buffer during route parsing, leading to a process crash and the closure of TCP port 554.
Affected products
- Tenda CP3 V3.0 V31.1.9.991
Timeline
- 2026-07-09: disclosed: CVE-2026-51605 published